SV-254262r1210265_rule
V-254262
SRG-OS-000185-GPOS-00079
WN22-00-000250
CAT I
10
Configure systems that require data-at-rest protections to employ encryption to protect the confidentiality and integrity of all persistent user-generated data and operating system-specific configuration data.
The encryption method implemented must use FIPS-compliant algorithms.
Verify systems that require additional protections due to factors such as inadequate physical protection or sensitivity of the data employ encryption to protect the confidentiality and integrity of all information at rest.
Note: If there is a documented and approved reason to omit data-at-rest encryption at the operating system level, such as encryption provided by a hypervisor or a disk storage array in a virtualized environment, this requirement is not applicable.
If there is no evidence that persistent user-generated data and operating system-specific configuration data are encrypted, this is a finding.
V-254262
False
WN22-00-000250
Verify systems that require additional protections due to factors such as inadequate physical protection or sensitivity of the data employ encryption to protect the confidentiality and integrity of all information at rest.
Note: If there is a documented and approved reason to omit data-at-rest encryption at the operating system level, such as encryption provided by a hypervisor or a disk storage array in a virtualized environment, this requirement is not applicable.
If there is no evidence that persistent user-generated data and operating system-specific configuration data are encrypted, this is a finding.
M
5485